PT-2021-14686 · Jenkins · Jenkins Config File Provider Plugin+1

Daniel Beck

·

Published

2021-04-21

·

Updated

2023-10-25

·

CVE-2021-21643

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Config File Provider Plugin versions 3.7.0 and earlier
Description The issue concerns incorrect permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins. This can be used as part of an attack to capture the credentials using another vulnerability.
Recommendations For Jenkins Config File Provider Plugin versions 3.7.0 and earlier, update to a version later than 3.7.0 to resolve the issue. As a temporary workaround, consider restricting access to the affected HTTP endpoints to minimize the risk of exploitation. Additionally, ensure that global Job/Configure permission is granted only to trusted users.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-21643
GHSA-3M3F-2323-64M7
RHSA-2021:2122
RHSA-2021:2431
RHSA-2021:2517

Affected Products

Jenkins
Jenkins Config File Provider Plugin